LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

zeroday.news ·

Federal agencies have issued an urgent warning regarding an active threat targeting critical infrastructure organizations, noting an evolution in attacker capabilities driven by the use of AI-generated exploit scripts. The National Security Agency (NSA) and the FBI, among other federal bodies, advised organizations to prioritize response efforts, particularly concerning programmable logic controllers (PLCs) used in critical sectors like energy, water, and agriculture.

The campaign specifically targets Siemens S7 Series PLCs, with threat actors employing AI-assisted development and exploiting known vulnerabilities. These unidentified attackers are conducting reconnaissance and developing capabilities against U.S.-based Siemens PLC installations. They are using internet scanning platforms to locate PLCs exposed online and deploying AI-generated exploitation scripts disguised as legitimate monitoring tools.

Federal agencies emphasized that this is not a theoretical risk, but an active threat that could lead to significant disruptions, safety incidents, equipment damage, data compromise, and cascading impacts across interconnected systems if poorly protected PLCs are exploited.

The use of AI to generate these exploitation scripts is considered a significant advancement in threat actor capabilities. It dramatically reduces the technical expertise and time required to develop functional Industrial Control System (ICS) exploitation scripts and malicious tools. AI also assists attackers in rapidly adapting to defensive measures, enabling them to create custom tools that mimic legitimate operational technology monitoring solutions.

While the advisory focuses on Siemens-specific content, it clarifies that this is part of a broader threat landscape. In July, federal agencies had reported that Iran-affiliated hackers were targeting PLCs from various manufacturers, including Schneider Electric, Rockwell Automation, and Allen-Bradley, in addition to Siemens.

The current activity is believed to be persistent reconnaissance, aimed at developing capabilities and preparing to cause operational effects against critical infrastructure. Siemens PLCs are widely used in the defense industry, as well as in water, power, and manufacturing sectors. Concerns were heightened two weeks prior to the advisory when numerous water utilities across at least 12 states reported cyber intrusions, also allegedly involving Iranian actors targeting PLCs. The latest advisory expands the scope of this campaign beyond water and wastewater facilities.

Organizations are strongly urged to isolate PLCs from the internet, install all available patches, and enable security tooling to monitor for threat activity. Experts note that AI has compressed the time between a vulnerability's publication and the availability of a working exploit script, making it accessible to individuals who previously lacked the technical skills to create them. Many end-users of PLCs may be unaware of their exposure, often due to third-party vendor configurations. The ultimate risk, if reconnaissance is allowed to mature, is not merely a data breach but a loss of view and control over physical processes, potentially leading to critical systems operating in an unmonitored state.

vulnerabilitynation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-19490critical

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

security

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

security

41 deceptive download sites show a real link, then send you somewhere else

A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.